Currently I am running the below query to generate a report based on appname,spacename,orgnameand foundation which takes longer to run(for the past 24 hours search). How do I create a summary index to efficiently use this query for faster results?
sourcetype="pcf:log" | eval reportcreatetime=strftime(now(), "%Y-%m-%d %H:%M:%S,%3N") | eval spanID_ = coalesce(spanid, SPANID, xb3spanid, spanId) |stats count(spanID) AS spanCount by reportcreatetime cfappname, cfspacename, cforg_name, foundation
However, it does not mean faster with data.It is only faster because the search is performed periodically and the results are created in advance.
There are disadvantages such as the need to recover manually if the regular execution fails.
It's a good idea to compare the pros and cons with "Accelerate reports".